CVE-2026-31856

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Increment operations on nested object fields using dot notation (e.g., stats.counter). The amount value is interpolated directly into the SQL query without parameterization or type validation. An attacker who can send write requests to the Parse Server REST API can inject arbitrary SQL subqueries to read any data from the database, bypassing CLPs and ACLs. MongoDB deployments are not affected. This vulnerability is fixed in 9.6.0-alpha.3 and 8.6.29.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:*
cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:*
cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha1:*:*:*:node.js:*:*
cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha2:*:*:*:node.js:*:*

History

13 Mar 2026, 18:54

Type Values Removed Values Added
First Time Parseplatform
Parseplatform parse-server
CPE cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:*
cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha1:*:*:*:node.js:*:*
cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha2:*:*:*:node.js:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) Parse Server es un backend de código abierto que puede ser desplegado en cualquier infraestructura que pueda ejecutar Node.js. Una vulnerabilidad de inyección SQL existe en el adaptador de almacenamiento de PostgreSQL al procesar operaciones de Incremento en campos de objetos anidados usando notación de puntos (p. ej., stats.counter). El valor de la cantidad se interpola directamente en la consulta SQL sin parametrización ni validación de tipo. Un atacante que puede enviar solicitudes de escritura a la API REST de Parse Server puede inyectar subconsultas SQL arbitrarias para leer cualquier dato de la base de datos, eludiendo CLPs y ACLs. Las implementaciones de MongoDB no se ven afectadas. Esta vulnerabilidad está corregida en 9.6.0-alpha.3 y 8.6.29.
References () https://github.com/parse-community/parse-server/releases/tag/8.6.29 - () https://github.com/parse-community/parse-server/releases/tag/8.6.29 - Product, Release Notes
References () https://github.com/parse-community/parse-server/releases/tag/9.6.0-alpha.3 - () https://github.com/parse-community/parse-server/releases/tag/9.6.0-alpha.3 - Product, Release Notes
References () https://github.com/parse-community/parse-server/security/advisories/GHSA-q3vj-96h2-gwvg - () https://github.com/parse-community/parse-server/security/advisories/GHSA-q3vj-96h2-gwvg - Patch, Vendor Advisory

11 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-11 18:16

Updated : 2026-03-13 18:54


NVD link : CVE-2026-31856

Mitre link : CVE-2026-31856

CVE.ORG link : CVE-2026-31856


JSON object : View

Products Affected

parseplatform

  • parse-server
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')